← Back
CWE-79

47,184 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,184)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Glpi Project
1Reports
Jun 17, 2026
Nov 17, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
GLPI - Reports plugin for GLPI Reflected Cross-Site-Scripting (RXSS). Type 1: Reflected XSS (or Non-Persistent) - The server reads data directly from the HTTP request and reflects it back in the HTTP response. Reflected...Show more
GLPI - Reports plugin for GLPI Reflected Cross-Site-Scripting (RXSS). Type 1: Reflected XSS (or Non-Persistent) - The server reads data directly from the HTTP request and reflects it back in the HTTP response. Reflected XSS exploits occur when an attacker causes a victim to supply dangerous content to a vulnerable web application, which is then reflected back to the victim and executed by the web browser. The most common mechanism for delivering malicious content is to include it as a parameter in a URL that is posted publicly or emailed directly to the victim. URLs constructed in this manner constitute the core of many phishing schemes, whereby an attacker convinces a victim to visit a URL that refers to a vulnerable site. After the site reflects the attacker's content back to the victim, the content is executed by the victim's browser. Show less
1Webpsilon
1Ultimate Tables
Jun 17, 2026
Nov 17, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Webpsilon ULTIMATE TABLES plugin <= 1.6.5 versions.
1Expresstech
1Quiz And Survey Master
Jun 17, 2026
Nov 17, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Multiple Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerabilities in Quiz And Survey Master plugin <= 7.3.4 on WordPress.
1Password Storage Application Project
1Password Storage Application
Jun 17, 2026
Nov 17, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
A cross-site scripting (XSS) vulnerability in the add-fee.php component of Password Storage Application v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the cmddept param...Show more
A cross-site scripting (XSS) vulnerability in the add-fee.php component of Password Storage Application v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the cmddept parameter.Show less
1Student Attendance Management System Project
1Student Attendance Management System
Jun 17, 2026
Nov 17, 2022
N/A· v4
4.8 MEDIUM· v3
N/A· v2
A vulnerability was found in Student Attendance Management System. It has been classified as problematic. Affected is an unknown function of the file createClass.php. The manipulation of the argument className leads to c...Show more
A vulnerability was found in Student Attendance Management System. It has been classified as problematic. Affected is an unknown function of the file createClass.php. The manipulation of the argument className leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-213846 is the identifier assigned to this vulnerability.Show less
1Ibm
1Business Automation Workflow
Jun 17, 2026
Nov 17, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Multiple IBM Business Automation Workflow versions are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potenti...Show more
Multiple IBM Business Automation Workflow versions are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 233978.Show less
1Scratch Wiki
1Scratch Login
Jun 17, 2026
Nov 17, 2022
N/A· v4
4.8 MEDIUM· v3
N/A· v2
The ScratchLogin extension through 1.1 for MediaWiki does not escape verification failure messages, which allows users with administrator privileges to perform cross-site scripting (XSS).
1Keyfactor
1Kefactor Ejbca
Jun 17, 2026
Nov 17, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Keyfactor EJBCA before 7.10.0 allows XSS.
1Keyfactor
1Primekey Ejbca
Jun 17, 2026
Nov 17, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
A stored XSS vulnerability was discovered in adminweb/ra/viewendentity.jsp in PrimeKey EJBCA through 7.9.0.2. A low-privilege user can store JavaScript in order to exploit a higher-privilege user.
1Amasty
1Blog Pro
Jun 17, 2026
Nov 17, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
The Preview functionality in the Amasty Blog Pro 2.10.3 plugin for Magento 2 uses eval unsafely. This allows attackers to perform Cross-site Scripting attacks on admin panel users by manipulating the generated preview ap...Show more
The Preview functionality in the Amasty Blog Pro 2.10.3 plugin for Magento 2 uses eval unsafely. This allows attackers to perform Cross-site Scripting attacks on admin panel users by manipulating the generated preview application response.Show less
1Hustoj
1Hustoj
Jun 17, 2026
Nov 17, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Hustoj 22.09.22 has a XSS Vulnerability in /admin/problem_judge.php.
1Equalweb
1Equalweb Accessibility Widget
Jun 17, 2026
Nov 17, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
EqualWeb Accessibility Widget 2.0.0, 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.1.10, 3.0.0, 3.0.1, 3.0.2, 4.0.0, and 4.0.1 allows DOM XSS due to improper validation of message events to accessibility.js.
1Backclick
1Backclick
Jun 17, 2026
Nov 16, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
An issue was discovered in BACKCLICK Professional 5.9.63. Due to insufficient output encoding of user-supplied data, the web application is vulnerable to cross-site scripting (XSS) at various locations.
1Tribalsystems
1Zenario
Jun 17, 2026
Nov 16, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Zenario CMS 9.3.57186 is vulnerable to Cross Site Scripting (XSS) via svg,Users & Contacts.
1Tribalsystems
1Zenario
Jun 17, 2026
Nov 16, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Zenario CMS 9.3.57186 is is vulnerable to Cross Site Scripting (XSS) via profile.
1Tribalsystems
1Zenario
Jun 17, 2026
Nov 16, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Zenario CMS 9.3.57186 is vulnerable to Cross Site Scripting (XSS) via News articles.
1Tribalsystems
1Zenario
Jun 17, 2026
Nov 16, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Zenario CMS 9.3.57186 is vulnerable to Cross Site Scripting (XSS) via the Nest library module.
1Guitar Pro
1Guitar Pro
Jun 17, 2026
Nov 16, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
A cross-site scripting (XSS) vulnerability in Arobas Music Guitar Pro for iPad and iPhone before v1.10.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload inserted into the name of an upload...Show more
A cross-site scripting (XSS) vulnerability in Arobas Music Guitar Pro for iPad and iPhone before v1.10.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload inserted into the name of an uploaded file.Show less
1Benbodhi
1Svg Support
Jun 17, 2026
Nov 16, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
The SVG Support plugin for WordPress defaults to insecure settings in version 2.5 and 2.5.1. SVG files containing malicious javascript are not sanitized. While version 2.5 adds the ability to sanitize image as they are u...Show more
The SVG Support plugin for WordPress defaults to insecure settings in version 2.5 and 2.5.1. SVG files containing malicious javascript are not sanitized. While version 2.5 adds the ability to sanitize image as they are uploaded, the plugin defaults to disable sanitization and does not restrict SVG upload to only administrators. This allows authenticated attackers, with author-level privileges and higher, to upload malicious SVG files that can be embedded in posts and pages by higher privileged users. Additionally, the embedded JavaScript is also triggered on visiting the image URL, which allows an attacker to execute malicious code in browsers visiting that URL.Show less
1Zoneminder
1Zoneminder
Jun 17, 2026
Nov 15, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
A Stored Cross Site Scripting (XSS) issue in ZoneMinder 1.36.12 allows an attacker to execute HTML or JavaScript code via the Username field when an Admin (or non-Admin users that can see other users logged into the plat...Show more
A Stored Cross Site Scripting (XSS) issue in ZoneMinder 1.36.12 allows an attacker to execute HTML or JavaScript code via the Username field when an Admin (or non-Admin users that can see other users logged into the platform) clicks on Logout. NOTE: this exists in later versions than CVE-2019-7348 and requires a different attack method.Show less